Privacy Policy

Effective: April 17, 2026 · Last updated: April 17, 2026
The short version: PinDrop reads your location only when you tap to save a place, stores your saved pins in a private cloud database tied to your Google account, and never sells your data or shows ads. You can delete everything by emailing us.

1. Who we are

PinDrop ("we", "us", "our") is a mobile application operated by Canburak Tümer, an individual developer based in Turkey. You can reach us at developer@canburaktumer.com.

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act, we act as the data controller for personal information collected through PinDrop.

2. What we collect

We collect the minimum information needed to run the app:

  • Account information — when you sign in with Google, we receive your email address, display name, profile photo URL, and a unique user identifier. We do not receive your Google password.
  • Location data — only the coordinates of the places you choose to save, captured at the moment you tap the save button. We do not track your location in the background or maintain a location history.
  • Place names — the label you give each saved pin (typed or transcribed from voice input).
  • Subscription status — whether you have an active PinDrop Pro subscription. Your payment details (card number, etc.) are handled exclusively by Apple or Google; we never see them.
  • Diagnostic data — anonymous crash reports and basic technical info (OS version, app version, device model) to help us fix bugs. This data is not tied to your identity.

3. What we do not collect

  • A continuous location history or movement tracking.
  • Contacts, photos, calendars, or other data from your device.
  • Advertising identifiers. PinDrop shows no ads.
  • Your voice recordings — speech recognition happens on your device, and we only receive the transcribed text after you save the pin.

4. How we use your data

We use the information listed above to:

  • Authenticate you and keep you signed in across devices.
  • Store and sync your saved places to every device you use.
  • Validate your PinDrop Pro subscription status.
  • Detect and fix bugs and crashes.
  • Respond to support requests you send us.

Legal basis (GDPR): we process your data under the legal basis of performance of a contract (to provide the service you asked for) and legitimate interest (to keep the service stable and secure). Where we rely on consent — for example, the initial location permission prompt — you can withdraw it at any time in your device's system settings.

5. Who we share data with

We do not sell your data. We share limited information with the third-party processors we rely on to run PinDrop:

  • Google Firebase (Google Ireland Limited / Google LLC) — authentication and database hosting. Firebase stores your account and your saved pins on Google's infrastructure. Firebase privacy policy.
  • RevenueCat (RevenueCat, Inc.) — subscription management. Receives an anonymous user ID and your purchase status; does not receive your location or your saved pins. RevenueCat privacy policy.
  • Apple App Store / Google Play — process your payments and report subscription events to us.

These providers act as our data processors: they handle data on our instructions and under contractual safeguards (Data Processing Agreements, standard contractual clauses for international transfers where required).

6. Where your data lives

Firebase stores data on Google Cloud servers in multiple regions (primarily the United States and EU). When data is transferred outside the EU, Google relies on European Commission–approved Standard Contractual Clauses to ensure an adequate level of protection.

7. How long we keep it

  • Account and saved pins — kept as long as your account exists. We delete them on request (see Section 9) and automatically after 24 months of inactivity.
  • Diagnostic data — kept for up to 90 days, then discarded or aggregated.
  • Support emails — kept for up to 24 months after our last exchange, then deleted.

8. How we protect it

All data in transit between the app and our servers is encrypted with TLS. Data at rest on Firebase is encrypted by Google. Access to production systems is restricted and protected by two-factor authentication. We do not store passwords: authentication is delegated to Google Sign-In.

9. Your rights

If you are in the EU, UK, California, or other regions with comparable laws, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — delete your account and all saved pins.
  • Portability — receive your saved places in a machine-readable format.
  • Objection & restriction — object to or restrict how we process your data.
  • Withdraw consent — revoke permissions at any time in your device settings.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email developer@canburaktumer.com from the address tied to your account. We respond within 30 days.

10. Children

PinDrop is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

11. Cookies and analytics

The PinDrop mobile app does not use cookies. Our website uses minimal cookies as described in our Cookie Policy.

12. Changes to this policy

If we make material changes, we'll notify you in the app and update the "Last updated" date above. Minor changes (clarifications, formatting) may be made without notice.

13. Contact

Questions, requests, complaints? Email developer@canburaktumer.com.